Craftcms/commerce
17 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Craftcms/commerce, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Craftcms/commerce CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 9 |
| 2026-03 | 7 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High2
- Medium14
Latest CVEs
The 15 most recently published vulnerabilities affecting Craftcms/commerce.
- GHSA-78vr-q6cf-c7p6Craft Commerce: Partial Payment Amount Without Lower Bound Validation—
- CVE-2026-31867Craft Commerce has a Potential IDOR in Commerce carts4.8
- CVE-2026-29177Craft Commerce has Stored XSS in Craft Commerce Order Details Slideout5.4
- CVE-2026-29176Craft Commerce has Stored XSS in Inventory Location Name4.8
- CVE-2026-29175Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking5.4
- CVE-2026-29174Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting8.8
- CVE-2026-29173Craft Commerce has Stored XSS while updating Order Status from Orders Table4.8
- CVE-2026-29172Craft Commerce has a SQL Injection in Commerce Purchasables Table Sorting8.8
- CVE-2026-25522Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation4.8
- CVE-2026-25490Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation4.8
- CVE-2026-25489Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation4.8
- CVE-2026-25488Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation4.8
- CVE-2026-25487Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation4.8
- CVE-2026-25486Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation4.8
- CVE-2026-25484Craft Commerce has Stored XSS in Product Type Name4.8
Product grouping is registry-driven, with AI assist and human review. How it works